DPDP Compliance at IvaBuddy
Indias Digital Personal Data Protection (DPDP) Act 2023 establishes how organizations must handle personal data. IvaBuddy was built with compliance as a foundation — not an afterthought. This page explains how we meet each key provision of the Act.
What Is the DPDP Act 2023?
The Digital Personal Data Protection Act, 2023 (DPDP Act) is India's comprehensive data protection law. Passed by Parliament in August 2023, it governs how organizations (“Data Fiduciaries”) collect, store, process, and share personal data of Indian citizens (“Data Principals”).
The Act gives Indian citizens significant rights over their personal data and imposes obligations on organizations to handle data responsibly. Non-compliance can result in penalties up to ₹250 crore.
Key Rights Under DPDP Act
How IvaBuddy Meets Each Provision
Grounds for Processing Personal Data
COMPLIANTIvaBuddy processes your personal data only for the purposes explicitly described in our Privacy Policy and with your informed consent at the time of registration. We do not process data for undisclosed or incompatible purposes.
Notice to Data Principal
COMPLIANTWe provide clear notice of what data we collect, why we collect it, and how it is used — before collection. Our Privacy Policy is written in plain language and is accessible at any time.
Consent Management
COMPLIANTYour consent is sought through a clear, voluntary, and specific mechanism. You can withdraw consent at any time by contacting us or by deleting your account. Withdrawal of consent will result in cessation of processing (with limited exceptions for legal obligations).
Obligations of Data Fiduciary
COMPLIANTAs a Data Fiduciary, IvaBuddy: (a) ensures accuracy of personal data; (b) implements security safeguards (AES-256 encryption, TLS 1.3, access controls); (c) deletes data after purpose is served or consent is withdrawn; (d) notifies the Data Protection Board and affected users within 72 hours of a data breach.
Right to Access Information
COMPLIANTYou can request a summary of all personal data processed by IvaBuddy at any time by emailing privacy@ivabuddy.com. We respond within 30 days as required.
Right to Correction and Erasure
COMPLIANTYou can update your personal information directly in your IvaBuddy account settings. To request complete erasure (right to be forgotten), contact privacy@ivabuddy.com. We will delete all personal data within 30 days, subject to legal retention requirements.
Right to Grievance Redressal
COMPLIANTWe have appointed a Grievance Officer (details below) who responds to all complaints within 48 hours. Unresolved complaints can be escalated to the Data Protection Board of India.
Processing Childrens Data
COMPLIANTIvaBuddy does not knowingly collect personal data from children under 18 years of age without verifiable parental consent. Our service is intended for business use by adults.
Processing of Personal Data Outside India
COMPLIANTAll IvaBuddy data is stored and processed exclusively in India (Mumbai and Delhi data centers). We do not transfer personal data outside India.
Security Measures Weve Implemented
AES-256 Encryption at Rest
All personal data stored in IvaBuddys systems is encrypted using AES-256, ensuring confidentiality in case of any unauthorized physical or logical access.
TLS 1.3 Encryption in Transit
All data transmitted between users and IvaBuddy servers uses TLS 1.3, the highest standard for transport security.
Access Controls & Audit Logs
Strict role-based access controls ensure only authorized personnel can access systems. All access is logged and audited.
Breach Response Plan
We maintain a documented incident response plan. In the event of a breach, affected users and the Data Protection Board are notified within 72 hours.
Data Minimization
We collect only the minimum personal data necessary to provide the service. We do not collect data beyond what is described in our Privacy Policy.
Data Retention Policy
Personal data is retained only as long as necessary for the stated purpose. Account data is deleted within 30 days of account deletion.
Grievance Officer & Data Principal Requests
Grievance Officer
Unresolved grievances may be escalated to the Data Protection Board of India once it is constituted under the DPDP Act 2023.
Submit a Request